What the ISM Code Can Teach Us About Risk: Part Two

Editor’s note: This is the second of a two-part article examining the risk-based thinking lessons to be learned from maritime safety and security protocols. You can read part one here.

The International Safety Management (ISM) Code brings a framework for safety through systematic management. It was introduced by the International Maritime Organization after several major maritime accidents revealed a common problem: The causes were rarely technical alone; instead, they were failures of management systems. The ISM Code, therefore, established a simple but powerful requirement, wherein shipping organizations must implement a documented safety management system (SMS) to ensure the safe operation of ships and the protection of the environment.

The principles embedded in the ISM Code offer valuable lessons for organizations operating in any uncertain environment. Many of these principles also resonate strongly with ISO 9001, the international standard for quality management systems. Let us examine a few of those connections.

Connecting the ISM code and ISO 9001

The ISM Code is not a technical manual for operating ships. Instead, it requires organizations to establish structured processes addressing leadership responsibility, risk assessment, operational control, training and competence, incident reporting, corrective action, and continual improvement. These requirements may sound familiar to anyone working with ISO management system standards such as ISO 9001 and others following the harmonized structure. In essence, the ISM Code recognizes a fundamental truth in that safe operations are the result of disciplined management systems, not individual heroics.

Establishing an SMS based on the ISM code and principles of ISO 9001 means planning for the unexpected. One of the most relevant principles in the ISM Code is the requirement to identify potential emergency situations and establish procedures to respond to them. Ships are required to plan for events such as fire, collision, grounding, machinery failure, person in water, and/or security threats or piracy. (Note that maritime security is covered by the International Ship and Port Facility Security Code and ISO 28001 covering security management systems for the supply chain). These procedures are not theoretical. Crews regularly conduct drills so that when an emergency occurs, the response is not improvised.

Organizations often interpret risk narrowly, focusing only on operational or financial risks. The ISM Code reminds us that effective management systems anticipate unexpected and low-probability events that can disrupt operations. In quality management terms, this is the discipline of considering what could go wrong and if people know their roles if (when) it does. It also means interrogating the system to determine how the organization will handle the ramifications of the adverse event.

Leadership and responsibility are important in maritime life. Another core principle of the ISM Code is clear authority and responsibility. Sections 5.1 and 5.2 require that on board a ship, there is no ambiguity about who is responsible for the safety of the vessel. The master has overriding authority. At the same time, as per section 4, the ISM Code requires those off the ship to support the master through a defined role known as the Designated Person Ashore (DPA). This individual provides a direct link between shipboard operations and top management. This structure reflects two key leadership principles: Authority must match responsibility and top management must remain connected to operational realities.

ISO 9001 expresses the same idea in a different context. As seen in clause 5.1 (“Leadership and commitment”) and clause 5.3 (“Organizational roles, responsibilities, and authorities”) leadership is required to ensure that the quality management system is integrated into the organization’s processes and that responsibilities and authorities are clearly assigned. Without this alignment, procedures quickly become paperwork rather than operational guidance.

In the case of mariners, competence and training are systematized. The International Convention on Standards of Training, Certification and Watchkeeping for Seafarers (STCW) ensures that seafarers are properly trained and certified for their duties. But beyond certification, maritime safety culture emphasizes something equally important: continuous drills and practice. Crew members rehearse emergency responses repeatedly. Fire drills, abandon-ship drills, and damage-control exercises are conducted not because emergencies are frequent; instead, it is because although they are rare, they are also highly consequential. This principle translates directly into quality management. Competence is not merely about qualifications; it is about preparedness to perform under pressure. Organizations that rely solely on written procedures without practical rehearsal often discover gaps only when a crisis occurs.

Learning lessons from incidents, as seen in ISO 9001’s clause 7.1.6 (“Organizational knowledge”) is integral to the SMS, making it a critical requirement of the ISM Code requiring the reporting and investigation of nonconformities, accidents, and hazardous occurrences. The purpose is not to blame, but to learn. Each incident becomes an opportunity to ask, “What failed in the system?” “What corrective action is needed?” and/or “How do we prevent recurrence?” Again, this is entirely consistent with ISO 9001’s approach to corrective action and continual improvement. The difference in the maritime world is that the consequences of failure can be immediate and severe. As a result, the discipline around incident learning is deeply embedded in the culture.

Risk decisions at sea and in maritime organizations need consideration about all key decisions, including how and when to transit dangerous areas. These decisions are rarely simple. They require balancing safety risks, commercial pressures, and regulatory requirements, including ever-changing statutory requirements of various contracting governments. This must be seen within the contexts of operational capability and the need to ensure crew welfare. The ISM Code does not dictate the decision. Instead, it ensures that the process for making the decision is structured and informed. This is perhaps the most valuable lesson for quality professionals. Management systems do not eliminate risk; they provide a framework for making better decisions about risk.

The ISM Code as a case study for risk-based thinking

Mariners have much to teach quality professionals on the use of the system approach for considering risks. For those working in quality assurance, auditing, or conformity assessment, the maritime experience offers several enduring lessons:

  • Systems matter more than individuals; therefore, while competent people are essential, reliable operations depend on structured systems.
  • Leadership must remain engaged in safety or quality, and this accountability cannot be delegated away.
  • Leaders must prepare for rare but high-impact events, because risk management is not only about what happens frequently.
  • Practice builds readiness.
  • Training and drills ensure procedures work under real conditions.

The takeaway is that there is a need to learn relentlessly from failure and use nonconformities as opportunities to strengthen the system.

The need to navigate uncertainty strengthens the importance of the ISM Code and/or ISO 9001 to inform leaders about risk and process management. For ship owners and masters, decision-making requires a complete and quick update of risks and other factors. For those who have spent a lifetime at sea, uncertainty is part of the profession. Mariners routinely navigate storms, mechanical failures, and complex navigational environments. Yet despite these uncertainties, global shipping remains remarkably reliable. More than 80 percent of world trade moves by sea, and the system functions with a level of safety and predictability that most industries take for granted.

The ISM Code, as well as ISO 9001, recognize that outcomes, whether safety or quality, depend on well-defined processes and leadership oversight. To mariners and quality professionals alike, I would advise another close look at your management system. Strengthen it. Maritime leaders ashore, like executives in the boardroom, must stay involved in assessing and mitigating risks to provide the best chance for safety, security, and success.

__

About the author

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

Home » Headquarters

What the ISM Code Can Teach Us About Risk: Part One

For centuries, individuals have sailed the sea, perhaps for their livelihood, perhaps for adventure, or perhaps for reasons of their own. Christopher Columbus, Ferdinand Magellan, James Cook, and countless others changed the world.

Today, sailing through international waters to meet the basic needs of the world brings challenges. Without merchant ships, tankers, bulk carriers, and container vessels, the global supply chain stops. Doesn’t the world owe these mariners all due safety and security?

I am a former seafarer who commanded submarines in the Indian Navy and then continued my career as a master in the merchant marine. Today, I am a subject matter expert in issues related to maritime safety and security. Given this background, I feel compelled to analyze what I hear and read about current events and provide a structure whereby the merchant marine industry might better prepare for any and all eventualities. The International Safety Management (ISM) Code, the International Convention on Standards of Training, Certification and Watchkeeping for Seafarers (STCW), and ISO 9001 all provide process-based approaches that can be used by those in this industry for planning and risk mitigation.

Most of us do not have to deal with high-risk challenges at sea. For those who do, however, there are guidelines they can use. As one example, the ISM Code provides some lessons into anticipating the unexpected and planning for these risks in a systematic manner.

In this article I will touch on how portions of the ISM Code connects to elements of ISO 9001 and provide input that might be useful to maritime leadership in ensuring quality assurance and conformity assessment based on risk and considering the context in which these organizations operate. This is guidance that applies to any of us, on the water or in a facility or factory.

Similarities between the ISM Code and ISO 9001

For professional mariners, a simple rule applies: Conditions that appear routine can change without warning. The ISM Code emphasizes preparedness for emergencies and abnormal situations. Section 8.1 requires the organization to establish procedures to identify, describe, and respond to potential emergency situations aboard the ship. In other words, the ISM Code requires organizations to plan not only for technical failures or weather hazards, but also for security risks and unexpected external threats. Navies may refer to this as an operational assessment, but (in Shakespearean language) a risk by any other name would still be a risk.

ISO 9001 expresses a comparable idea through the requirement for risk-based thinking. As emphasized in clause 6.1.1, the organization shall determine the risks and opportunities that need to be addressed to give assurance that the quality management system can achieve its intended results.

From a management systems perspective, the broader lesson is clear: Organizations must plan for situations that may appear unlikely until they occur. For a ship’s captain or master, that planning may involve security drills, contingency routing, and coordination with naval authorities. For a quality manager or organizational leader, it may involve supply chain disruption, cybersecurity incidents, or geopolitical shocks. Ultimately, the decision on whether to sail should be based on a proper risk assessment. Events at sea sometimes remind us, in stark terms, why disciplined safety and command systems matter. What makes an incident significant in the context of this discussion is the reminder of just how quickly circumstances can change at sea.

Within ISO 9001, the context of the organization (clauses 4.1 and 4.2) leads to risk appreciation (clause 6.1). All of this must be integral parts of the maritime management system, at sea or ashore.

This is precisely why the ISM Code emphasizes preparedness for emergencies and abnormal situations as per section 8.1. Good organizations connect real maritime events with risk-based thinking. They understand that commercial interests must mesh with the emergency planning sections in the ISM Code. This understanding is also found in ISO 9001, specifically in clause 6 (“Planning”) and clause 8 (“Operation”).

Expecting the unexpected

My own appreciation for disciplined systems thinking was shaped long before the ISM Code was widely implemented in commercial shipping. During my years in the Indian Navy, I had the privilege of commanding vessels, first on F-class boats and later through service on a Charlie II-class submarine. Submarines operate in an environment where uncertainty is not theoretical and the margin for error is extremely small. Any failure in equipment, communication, or procedure can quickly become critical. What keeps submarines safe is not individual brilliance on the part of a captain or crew. That is part of it, of course, but even more important is the relentless adherence to procedures and constant preparation for contingencies. Before every patrol, the crew repeatedly rehearses emergency actions such as flooding drills, fire drills, loss of propulsion, and loss of power. Each crew member knows precisely where to go, what valve to operate, and what sequence of actions to follow. These procedures are not simply found in written manuals. They are practiced until they become instinctive.

At that time, we did not describe this discipline in terms of “process-based management systems,” but that is exactly what it was. The system existed to ensure that when the unexpected occurred, as it inevitably does at sea, the crew would not rely on improvisation alone. The response would already be embedded in the system and in themselves. Years later, when I sailed as a master in the merchant marine and then began to work with ISO management systems, I recognized the same principles expressed in a different language. ISO 9001 requires organizations to establish, implement, and maintain the processes needed for the quality management system and their interactions, as per clause 4.4 (“Quality Management System and its Processes”). Section 1.2 of the ISM Code similarly requires organizations to ensure safe practices in ship operation and a safe working environment. Different industries, different terminology, but the underlying idea is identical: Safety, quality, and reliability are the result of preparation and training, not simply reacting well to emergencies.

I can confirm through my experience that this reflection is not merely theoretical. It comes from first-hand experience wherein I led teams and where preparation truly mattered. This background gives me a clear perspective on risk, command responsibility, and disciplined procedures under uncertainty. This perspective can make a very compelling bridge between maritime safety management (ISM/STCW) and organizational quality systems (ISO 9001).

As we consider dangerous situations on or in the water, we can see what the ISM Code and ISO 9001 (in addition to other maritime protocols and ISO standards) can teach us about risk in uncertain times. In today’s volatile world, commercial shipping once again finds itself navigating geopolitical tension. News headlines remind us that vessels may need to transit waters where the risks are not merely commercial, but also matters of safety and survival. For those who have spent a career at sea, such circumstances are not entirely unfamiliar. The maritime profession has long recognized that uncertainty is inherent to operations. Ships sail through storms, equipment failures, and occasionally conflict zones. Yet despite these uncertainties, shipping remains one of the safest and most reliable global industries. This is not an accident. Much of that safety culture comes from the ISM Code, supported by training standards such as STCW. These frameworks provide reliable, structured guidance on how organizations anticipate risk, prepare crews, and maintain operational control.

In the next part of this two-part article, we will further discuss the framework of maritime systems and how they relate to risk and ISO 9001.

__

About the author

Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.

Integrated Management System: Combining ISO 9001 and ISO 14001 Without Doubling the Work

An integrated management system (IMS) combining ISO 9001 (quality) and ISO 14001 (environment) is not double the work – it’s half the effort. Built on the shared Annex SL High Level Structure, an IMS eliminates siloed audits, redundant documentation, and conflicting objectives, replacing them with a single, unified framework for operational excellence.

The harmonized standards were not available till about 2012. Yet at QMII, we talked about an integrated approach to management and worked with organizations on the advantages of the integrated management system (IMS) or combined management systems. Why this discussion? It is a classic efficiency and silos battle. Many organizations treat ISO 9001 (quality management system, QMS) and ISO 14001 (environmental management system, EMS) as two separate burdens, often managed by two different departments that barely speak. With the emphasis on ISO 45001 (occupational health and safety, OHS) in recent times, we can see that an environmental impact could cause health consequences. Yet I see large organizations with siloed departments. In this short article I want to challenge and leave this for discussion that this double the work myth is incorrect and how the Annex SL harmonized structure makes various standards natural partners.

This myth of the parallel path must be demystified at the highest level. In many boardrooms, ISO is a word associated with binders, audits, and administrative fatigue. When a company decides to pursue both quality (ISO 9001) and environmental (ISO 14001) and other standards, the gut reaction is often to build two or as many separate systems as for each applicable standard. My first question is why manage your business as if your quality goals, OHS goals, asset management goals, crypto security goals, business continuity goals and your environmental impact etc. happen in different buildings? An integrated management system (IMS) isn’t just possible, it is the only way to achieve true operational harmony and genuine continual improvement.

The foundation of the integrated management system: Annex SL (High Level Structure). The secret weapon for harmonization is Annex SL. Most of the harmonized standards share identical core structures, meaning the skeleton of the management system is already the same. They share terms, definitions, and most importantly, their core clauses.

If I put this in phases, then the phase 1 would be to look at harmonizing the context and leadership. Let us simplify this discussion take just two standards, ISO 9001 and ISO 14001. At the start of both standards, the requirements are nearly indistinguishable in intent:

  • Clause 4: context of the organization would then not require doing two SWOT analyses, just do one. Identify your internal and external issues once. Under clause 4.2, the organization can identify the interested parties. A customer (quality) and a local regulatory body (environment) are both stakeholders. Managing them in one register ensures that environmental compliance doesn’t accidentally bottleneck quality delivery.
  • Clause 5: leadership and commitment where most un-integrated systems fail. Management shouldn’t have to attend two different management review meetings. Integration forces leadership to view quality and sustainability as two sides of the same strategic coin. One policy, one set of roles, and one unified vision based on risks across the organization.

The phase 2: then I would say would be the integrated planning and risk. This is where the heavy lifting of harmonization happens.

  • Clause 6.1: Actions to address risks and opportunities — a cornerstone of risk-based thinking in both standards. In ISO 9001, the organization looks at risks to product quality. In ISO 14001, you look at environmental aspects and impacts. By combining these in a single integrated management system, you see the full picture. For example, a chemical change in manufacturing might improve product durability (9001) but increase hazardous waste (14001). If these systems aren’t harmonized, you solve one problem only to create another.
  • Clause 6.2: objectives and planning harmonization enables the organization to set smart objectives that satisfy both standards simultaneously, such as reducing material waste which then lowers costs (quality) and reduces environmental footprint (environment).

Phase 3: could be unified support and operation and would meet the requirements of clauses 7 & 8 of both standards:

  • Clause 7: support would not need two sets of document control procedures or two different training programs. Clause 7.2 (competence) and clause 7.3 (awareness) can be handled through a single employee onboarding process.
  • Clause 8: operation while ISO 9001 focuses on operational control of the product and ISO 14001 focuses on life-cycle perspective and emergency response, they both live on the shop floor. Integrating these means the organization’s standard operating procedures (SOPs) include environmental safeguards alongside quality checks.

Phase 4: would then be a great advantage to the organization as it would provide the single pane of glass evaluation with the greatest efficiency gain in an IMS coming during the evaluation phase.

  • Clause 9.2: internal audit would be simpler and give more productivity. After all, why pay for or conduct two separate audits? A harmonized internal audit looks at a process from start to finish, checking for quality defects and environmental non-conformance in one walk-through.
  • Clause 9.3: management review would bring quality data and environmental performance to the same table and would allow executives to make resource allocation decisions based on the whole business, not just a siloed report.
  • Clause 10: Improvement. Corrective actions (clause 10.2) should follow the same root-cause analysis (RCA) path within the PDCA (Plan-Do-Check-Act) cycle. Whether a part failed a stress test or a spill occurred, the process for fixing the system and preventing recurrence is identical. The risks are common.

The concluding phase would bring the organization to move from fragmentation in the approach to bringing harmony by combining ISO 9001 and ISO 14001. It isn’t just about saving paper or reducing audit days. It’s about organizational maturity. When organizations harmonize these systems, they stop treating quality and environment as extra tasks and start treating them as the standard way of doing business. For those who still don’t appreciate the value they need to look at the bottom line. Less redundancy, clearer communication, and a unified strategy are the hallmarks of a company that isn’t just compliant, but competitive.

The primary standard ISO 9001 is being updated, and the new version will be available in September 2026. ISO 14001 is already available in the updated version. The update of other standards including the aerospace and other industry standards will follow.  The change to clauses in the updates of the standards is minimal. It means the structure will be same; the emphasis is in the implementation. As organizations move toward ESG (Environmental, Social, and Governance) reporting, having a harmonized ISO 9001/14001 integrated management system (IMS) provides the verified QMS and EMS data needed to back up those high-level sustainability claims.

Then there is the cost saving angle too. Human ROI of systems engineering must be considered. In the world of ISO, we often talk about process efficiency, but we forget that stressed employees are the primary drivers of hidden costs. When a system is fragmented, people are forced to become the glue manually reconciling data, filling out redundant forms, and bracing for audits. That glue is expensive, and eventually, it cracks. There is a need to bridge that connection. Stress drains the bottom line, often termed the friction tax. In a siloed organization, employees pay this friction tax daily perhaps as a decision fatigue when quality and environmental objectives conflict, managers hesitate. Hesitation delays production. Then another one of the common costs is the audit anxiety. If an internal audit feels like a blame game session because the paperwork is a mess, morale drops. Low morale leads to higher turnover and the cost of replacing skilled employees are often twice their annual salary. The need to make double entries wherein technicians must log a chemical spill in the quality log and also in the environmental log. It is not just annoying but a sheer waste of billable hours.

The logic of the harmonized integrated management system therefore provides a clear ROI. Organizations can visualize the connection for example in reduced waste (clause 8.1) where an integrated process ensures that doing it right the first time (quality) also means using only what is necessary (environmental). Less scrap material means lower disposal costs and lower procurement costs.

Leaderships understand the importance of a proactive system. Being predictive is better than a system which is reactive. If the organization is all the time firefighting the stress will be more. A harmonized system uses clause 6.1 (risk management) to prevent fires before they start. It is significantly cheaper to maintain a machine (preventing both a quality defect and an oil leak) than it is to clean up a disaster. Streamlined training is another plus of the harmonized system. By integrating requirements, you reduce the time employees spend in training rooms and increase the time they spend on the value-add line.

The ultimate goal of any management system isn’t to pass an audit. It is to provide a stable platform for the business to grow. When we treat ISO 9001 and ISO 14001 (as also other relevant standards) as separate entities, we inadvertently bake friction into our corporate DNA. We create a system where the left hand ignores the right, and the employees the organization’s most valuable assets, pay the price in stress and burnout. By harmonizing these systems into a true integrated management system (IMS), organizations eliminate the friction tax. Administrative noise is replaced with operational clarity. When a system is integrated, clause 10 (Improvement) ceases to be a chore and becomes a natural byproduct of a focused workforce. In summing up I would say less complexity leads to less stress. Less stress leads to fewer errors. Fewer errors lead to less waste and higher ROI. For those who still view integration as a nice-to-have, remember in an increasingly volatile market, the most successful companies aren’t the ones with the most binders on the shelf they are the ones with the most streamlined, intuitive, and stress-free processes. Integrating ISO 9001 and 14001 isn’t just a technical exercise, it is a commitment to organizational health. When your management systems work in harmony, your people can finally stop managing the system and start managing the business.

About the Author:

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

The Hidden Signals of Process Breakdown

When implementing management system, the organizations are really not trying to reinvent the wheel.  The availability of ISO standards gives us a well tried, over the years updated approach in terms of the available clauses. The PDCA (plan, do, check and act) cycle approach in the harmonized standards enables designing an effective management system, monitoring it and updating it to not just produce confirming products and services but also to use inputs at the check stage to continually improve it. Yet the systems fail. Non-conforming products are released. Is there then an anatomy of a quiet failure? Indicators that will enable discovering these signals proactively. If that can be analyzed organizations would appreciate these hidden signals of the system breakdown and take proactive measures. Risks and trends are data driven. Can we expect our auditors to proactively recognize these.

There is the lagging indicator trap between being reactive and proactive. Up to the 2015 version of ISO 9001 (and equivalent industry specific standards in the harmonized structure) preventive action was taken based on data, invariably at the act stage of the PDCA cycle. From the 2015 version onward clause 6.1 introduced the risk appreciation requirement at the plan stage itself and then throughout the work cycle. Separating knowledge (clause 7.1.6 of ISO 9001) from competence (clause 7.2 of ISO 9001), has introduced us to corporate knowledge in terms of lessons learnt. Leadership in analyzing changing context and risk thereof should be on the lookout for indicators.  Therefore, the PA (preventive action) concept needed a change to risk. The idea was not to throw the baby with the bathwater. NC (non-conformity) did drive correction and CA (corrective action), however, as the organization collected data it became proactive wherein data drives risk and trends. Waiting for a nonconformity (NC) is a reactive strategy. Therefore, organizations should not be we waiting for NCs. By the time an NC appears, the financial or quality damage is already done. Being proactive therefore, is the need of a functioning system.

With the ISO 9001 revised 2026 version expected in September 2026 there is, quite correctly the need to strengthen the check stage. The organizations will expect better auditing instead of just a check list being completed. The auditor’s sixth sense to ask better questions and to establish how the system is working will be important. Just having a frame and expecting it to do magic and pinpoint failures of the system is not sufficient, but the need is for a high-level pattern recognition. The skilled auditors look for the erosion of intent, where the way work is done drifts away from how it was designed. They need is to provide these inputs during audits to the leadership.

For the organizations and the auditors there are many signals of this hidden failure. There is the tribal knowledge drift as recognizing the symptoms, where the question is: “how do you do XXX?” and the employee reaches for a handwritten sticky note or a personal notebook instead of the official SOP (standard operating procedure). The hidden meaning here is that the official process is likely too rigid, outdated, or inaccessible. This is indicative of a workaround culture in its infancy. Then there is the risk scalability. The process lives in heads, not in the systems. This is indicated by when those people leave, the process collapses. Technically it was not a system. The system instead of being a working process was dependent on individual competence.

Good auditors are conscious of another signal indicated by the language used and the linguistic friction. The Symptom here is in phrases like “we usually just…”, or “on a good day, we…”, or “that’s just how we have to do it.” In these and similar cases the hidden meaning is indicating to the organization and to the auditors that the standard process is no longer the path of least resistance. For a good auditor the clue is the hesitation or glance-exchanges between team members when answering simple procedural questions. Looking ahead at expectations of the ISO 9001, 2026 version of the standard the auditors need to be conscious of how the system is actually working, working or not working.

The next signal to watch out for could be the ghost workload (shadow processes) indicated by the excessive use of excel trackers to manage data that should be in the ERP/QMS, or the need for frequent offline meetings to fix recurring errors or the use of tiger teams to cover the back log. The hidden meaning of this should be clear. The formal system is failing to provide the necessary utility. Also, that the risk is not being proactively data driven. Data integrity and lack of visibility by the management leads to the leadership  seeing a green dashboard, when the reality is red and it is showing a mirage of being held together by manual labor.

Related to this is the physical and digital clutter. The clear symptom of this e.g.  in a physical plant, it’s unlabeled bins or “red tag” areas that haven’t moved in months. In a digital space, it’s numerous versions of the same document with names like final_vrn2_use_this.pdf. etc. The implication of this is the loss of 5S discipline (sort, set in order, shine, standardize, sustain). Clutter is a visual representation of a mind and of a process that has lost its focus.

Good auditors must also consider the human element and its connected emotional cues like the defensiveness vs. transparency conflict. If a process owner is overly protective of their territory, they are often hiding a breakdown they don’t know how to fix. It can also be a conflict between fatigue and apathy leading to when and why? This is answered with rationalization, because that’s the rule, the connection between the task and the value (quality) has been severed.

My concluding thought is to prepare for implementation of ISO 9001:2026 (expected in September 2026). In preparing understand that the auditors should be becoming proactive auditors. They need to shift the goal and change their attitude. The goal isn’t to catch people; it’s to catch the process before it fails them and therefore the organization. The value add is that a skilled auditor saves the company money by identifying these frictions before they turn into a notice of inspection by a statutory body, a client, a recall, or a lost certification. Organizations should expect their auditors to catch these hidden signals of process breakdown timely and report them. A good audit report should include these and this should be the expectation.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Auditing Risk Management: How Experienced Auditors Identify Risks That Aren’t Listed in the Risk Register.

Organizations today rely heavily on risk registers to track and manage potential threats. Risk registers are useful tools, and they document known risks, assess their likelihood and impact, and assign ownership for mitigation actions. They help leadership visualize risk exposure and provide a structured way to prioritize responses.

However, risk registers have their limits. Experienced auditors know something critical, that the most damaging risks are often the ones that never appear in the register. A risk register represents what the organization already knows or believes it knows. The context of the organization changes. A risk register reflects the thinking of the team that created it. But risks evolve, environments change, and assumptions become outdated. As a result, relying solely on the documented register can create a false sense of security. Seasoned auditors understand that their responsibility goes beyond verifying that risks are listed and mitigations are documented. Their deeper role is to identify blind spots and record risks that exist outside the documented system. This is where experience, professional skepticism, and systems thinking become essential. Skilled auditors recognize patterns, inconsistencies, and subtle signals that indicate hidden risks. QMII specializes in risk and with our forty plus years in the system field, in this article, we explore how experienced auditors uncover risks that never make it into the risk register and why this capability is essential for effective risk management.

The questions therefore are, why risk registers miss critical risks. I think, before examining how auditors uncover hidden risks, it is important to understand why risk registers are incomplete.

Risk registers reflect perception and often not the reality. Risk registers are typically compiled during structured workshops or periodic reviews. Participants identify risks based on their knowledge and experience. But human perception is limited. People tend to list:

  • Risks they have seen before.
  • Risks that are already familiar.
  • Risks that are easy to articulate.

But unfamiliar or emerging threats often remain invisible. For example, a manufacturing team might focus heavily on supply chain delays while overlooking risks related to cybersecurity vulnerabilities within their operational technology systems. Experienced auditors recognize this limitation and therefore treat the risk register as a starting point, not the final word.

Then there is the organizational bias which influences risk Identification. Risk registers can be influenced by internal politics or cultural pressures. Some risks may be downplayed because:

  • They reflect poorly on leadership decisions.
  • They expose systemic weaknesses.
  • They challenge existing strategies.

In such cases, risks may be intentionally or unintentionally omitted. Auditors who understand organizational dynamics pay attention not only to what is documented, but also what is missing.

Please also consider that risks often evolve faster than documentation. The modern risk landscape changes rapidly due to:

  • Technological advancements.
  • Regulatory changes.
  • Market disruptions.
  • Geopolitical instability.

Risk registers are often updated annually or quarterly. But emerging risks can develop far faster than review cycles. Experienced auditors therefore examine current conditions, not just documented assessments. The experienced auditors detect unlisted risks. The difference between routine auditing and expert auditing lies in how auditors think. Experienced auditors do not simply verify compliance. They analyze systems, behaviors, and signals that reveal underlying vulnerabilities. The ISO 9001 version expected in September 2026 expects organizations to go beyond check lists and see how their system works to produce confirming products and services.  The auditors of the future must work to providing these inputs. Several approaches distinguish their work.

The primary is developing the attitude and aptitude where the auditors look for process weaknesses, not just risk entries. Experienced auditors start by examining processes rather than documentation. Instead of asking: “Is this risk listed in the register?” They ask: “Where could this process fail?” Every process contains inherent vulnerabilities. Skilled auditors identify points where failure could occur, including:

  • unclear responsibilities.
  • lack of monitoring.
  • excessive reliance on manual steps.
  • insufficient controls.

For example, if a company relies heavily on one individual to approve high-value financial transactions, an auditor immediately recognizes concentration of authority risk, even if the risk register never mentions it. In other words, auditors uncover risks by studying how work actually happens.

Observing operational reality is another positive trait in an auditor. Documentation often describes how processes are supposed to work. But experienced auditors know that actual practice frequently differs from documented procedures. They therefore observe operations directly by speaking with frontline staff, watching processes in action and asking open-ended questions. These conversations often reveal informal workarounds, shortcuts, or unofficial practices that introduce risk. For instance, employees might bypass a cumbersome control procedure to meet production deadlines. While the process appears compliant on paper, operational reality tells a different story. This gap between documented procedure and actual practice often exposes hidden risks.

Auditors can add value by providing inputs in audit reports which connect risks across functions. Risk registers are frequently organized by departments. Each function identifies its own risks independently. But real risks often emerge between functions, where responsibilities intersect. Experienced auditors look for these interdependencies. Examples include IT changes affecting operational reliability, procurement decisions impacting regulatory compliance or sales commitments creating financial exposure and so on. When risks are examined in isolation, these connections may never be recognized. Auditors with systems thinking identify risks that arise from interactions between processes.

Another useful tip I could share with auditors would be to learn the art of questioning assumptions. A hallmark of experienced auditors is professional skepticism. They challenge assumptions that others take for granted. Common assumptions include:

  • “This control has always worked.”
  • “That vendor is reliable.”
  • “This system cannot fail.”

History repeatedly shows that risks often emerge when organizations become overly confident in their controls. Complacency is in itself a risk. Auditors therefore test assumptions by asking questions as, what happens if this control fails? Or what alternative scenarios could occur? Or perhaps, what early warning signs might exist? This mindset helps auditors uncover risks that have never been formally considered.

Identifying early warning signals should be the organizations’ role. However, it is often missed as the organization gets acclimatized to it. Hidden risks rarely appear suddenly. They often produce early signals which even if missed by the organization can be observed by the experienced auditor. These signals may include:

  • recurring minor incidents.
  • increasing process delays.
  • rising customer complaints.
  • frequent control overrides.

Individually, such signals may appear insignificant. But collectively, they may indicate deeper systemic risks. Experienced auditors are trained to recognize these patterns. They understand that small anomalies often precede major failures.

Therefore, the role of auditor experience is vital. Technical knowledge alone does not enable auditors to detect hidden risks. Experience plays a critical role. Experienced auditors develop several capabilities over time for example their ability to see a pattern recognition. Years of exposure to different organizations allow auditors to recognize patterns that others miss. They may recall similar conditions that led to failures in other organizations and apply those lessons proactively.

Systems thinking is another quality experienced auditors possess. They may be auditing a few selected processes in a particular audit; however, the system perspective must be kept in mind. Experienced auditors understand organizations as interconnected systems. They see how decisions in one area influence outcomes in another. This perspective helps them identify risks that arise from system complexity rather than isolated failures.

Experienced auditors have judgment and intuition. They know that while auditing they must remain evidence based.  Seasoned auditors also develop professional intuition. We are not recommending experience as the basis for audit decisions. Requirements should remain the primary basis. Yet this intuition arises from accumulated experience and allows auditors to recognize subtle indicators that something may be wrong, even when documentation appears complete. They therefore ask questions to unearth hidden risks.

Strengthening risk management through auditing is a desirable trait. When auditors identify risks outside the risk register, they provide tremendous value to leadership. Their insights help organizations:

  • identify emerging threats earlier.
  • improve risk identification processes.
  • strengthen internal controls.
  • enhance organizational resilience.

Most importantly, they shift risk management from a static checklist to a dynamic learning process. Organizations that encourage auditors to explore beyond the register benefit from more realistic and proactive risk oversight. Auditors must start moving beyond the checklist mindset. In some organizations, audits become overly focused on verification. Inexperienced auditors tend to look at questions in terms of, is the risk listed or is the mitigation documented or is the review completed? While these checks are necessary, they represent only the baseline of effective auditing. Experienced auditors move beyond checklist thinking by asking deeper questions:

  • What risks might exist that we have not yet identified?
  • Where could the system fail under stress?
  • What assumptions might be wrong?

This shift transforms auditing from a compliance exercise into a strategic capability.

In conclusion I would opine an experienced auditor is like a risk detective. Risk registers remain valuable tools. They provide structure, accountability, and visibility into known risks. But they cannot capture every emerging or hidden threat. That is why experienced auditors play such a crucial role in risk management. By observing operations, questioning assumptions, connecting systems, and recognizing subtle warning signs, skilled auditors identify risks that others overlook. In many cases, their ability to detect these hidden risks prevents costly failures long before they occur.

Ultimately, the most effective auditors behave not just as compliance reviewers, but as risk detectives who are constantly searching for what the organization has not yet seen.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Why Most ISO Audits Miss System Failure Signals – And How Experienced Auditors Detect Them

I have always valued the process-based management system (PBMS) approach based on the ISO standards as the best start to designing and implementing a management system that produces confirming products and services. Over time with continual improvement the system should give the ROI (return on investment). The management system is not a magic trick, agreed, it all depends on the implementation. The system starts in a responsive manner where NCs (non-conformities) drive correction and CA (corrective action). The system then matures and becomes proactive when data drives risk and trends. The internal audits should give the leadership the inputs to better resource and continually improve the system.  Yet I see organizations end up with a “checklist-style” audit where these frustrating audits do not provide the inputs to improve the system. It is often because audits treat a living system like a static inventory. Most audits miss signals because they focus on conformity (did you do what you said?) rather than capability (does the process achieve the intended result?). The intend should be to bridge the gap between “compliance” and “performance.”

The illusion of compliance pays the price. Most ISO audits fail to detect systemic rot because they are designed to find missing records, not broken logic. That is because auditors fall into the checklist trap. Standard auditors often follow a linear path. If the “management review” happened and the minutes exist, they check the box. Then there is the “paper thin” system where organizations have become experts at “audit-ready” documentation that masks operational chaos. Finally, the auditors focus on output and not on outcome during the audits, they often verify that a process ran but fail to ask if the process is healthy.

The question then is why the “signals” are missed? System failures rarely happen overnight; they emit “smoke” long before the fire. Standard audits miss these because:

  • Siloed Auditing: Auditors look at Department A and Department B separately, missing the friction and “white space” between them where most failures occur.
  • Sampling Bias: Auditors often let the guide choose the records. Experienced auditors know that the most telling data is usually in the “messy” folders the guide is trying to steer them away from.
  • Metric Manipulation: If a KPI is 99% green but the customer is complaining, the system is failing. A standard audit sees the 99% and moves on.

Therefore, the need is to see how experienced auditors “hear” the system. Veteran auditors move beyond the “what” and the “where” to the “how” and the “why.” They use a PBMS lens to detect:

  • The “work-around” signal, when employees have a “shadow” spreadsheet or a personal notebook to get the job done, the formal system has already failed.
  • The “quality debt” signal where recurring “minor” non-conformities are often symptoms of a single “major” systemic bypass.
  • Language patterns when experienced auditors listen for phrases like “we usually do it this way, but for the audit…” or “that person is the only one who knows how that works.”

The need is for auditors to transition from “auditing for points” to “auditing for risk”. To truly add value, the audit must evolve into a diagnostic tool.

  • Vertical vs. horizontal auditing where instead of checking a department, follow a single order from “quote to cash” to see where the process bleeds.
  • The “stress test” approach where auditors ask, “what happens if this person is out?” or “what happens if this supplier fails?” to test system resilience.

The key takeaways so far could be summarized as:

  • The process is the patient. Treat the audit like a medical check-up. Don’t just check the pulse; look at the lifestyle and the underlying vitals.
  • Stop re-inventing, start refining.  Since you believe in standards, emphasize as an auditor, that the ISO standards already require a process approach. Most people just ignore it in favor of the easier “clause-by-clause” approach.

As an example, we can consider a perfect paper audit that is followed by a major product recall, as indicative of illustrating the compliance-performance gap. The occurrence of a mishap, or a rejected product soon after a perfect audit should make an organization investigate its auditing effectiveness. It is necessary to take the great deep-dive and shift the focus from “did they follow the process?” to “is the process actually functioning?” is what separates a tick-box auditor from a system specialist.

In a standard audit, if the records are signed and the dates match, the process is marked “effective.” But experienced auditors know that a perfectly documented process can still be a failing one. To detect the signals most miss, you must look at the friction points the places where the “official” system meets human reality. Avoid the Illusion of compliance. In the world of ISO standards, there is a dangerous comfort in a “clean” audit report. As a specialist in process-based management systems (PBMS), I have always believed in the power of standards. Why re-invent the wheel when a global framework for excellence already exists? Yet we see it constantly: organizations pass their surveillance audits with flying colors, only to suffer a catastrophic service failure, a massive product recall, or a sudden dip in profitability weeks later.

In conclusion I would caution organizations, audit clients and auditors to stop auditing the paper, and to start auditing the pulse. If we continue to treat ISO audits as a “pass/fail” hurdle for a certificate, we do a disservice to the discipline of management. A standard is not a ceiling; it is a floor. It is the “wheel” that shouldn’t be re-invented, but it must be maintained, balanced, and aligned.

Any organization’s call to action may be called the “value-add” challenge where the organization changes the lens for the next audit cycle to:

  • Ditch the clause-by-clause audit to follow a single order from “quote to cash” rather than checking department folders.
  • Search for the “shadows” and look for the post it notes and cheat sheets. They show you where the formal system is failing to support the staff.
  • Ask “why” Five times to root cause the system. Refuse to accept “human error” as a root cause. Dig until you find the process flaw. Blaming is easy but not the answer.

The goal of a Process-Based Management System is to create a resilient, predictable, and scalable organization. Let’s stop auditing for compliance and start auditing for capability. At QMII we train our auditors for this.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Audit Focus Areas Under ISO 28000 for 2026 and beyond

In this article on ISO 28000 I want to emphasize the audit focus areas based on what 2025 revealed and what auditors must prioritize in 2026 and beyond. The emphasis is from mere compliance to resilience leading to secure supply chains.

The year 2025 can be seen as a watershed moment for supply chain security management systems. Global supply chains were subjected not to one dominant crisis, but to a convergence of pressures, geopolitical instability, regulatory fragmentation, cyber intrusion, logistics disruption, and heightened stakeholder scrutiny. For organizations certified to ISO 28000, and for auditors charged with assessing conformity, this period exposed an uncomfortable truth, many supply chain security management systems were compliant in form, but brittle in practice.

As we look toward 2026 and beyond, ISO 28000 audits must evolve to meet these challenges. Agreed organizations must not wait for audits to ensure continual improvement, act on risks and to use the opportunities for improvement (OFI). However, this too is true that NCs (nonconformities) drive correction and CA (corrective action). As such audits play a minor part in providing inputs at the check stage of the PDCA (plan-do-check-act) cycle. Therefore, the question is no longer whether organizations have established a supply chain security management system, but whether that system is capable of sensing change, absorbing shocks, and adapting under stress. ISO 28001, as the supporting guidance standard, provides a valuable lens through which this shift can be framed, particularly in relation to risk assessment, security planning, and operational controls.

This article reflects on what audits in 2025 revealed and outlines the audit focus areas that will define credible, value-adding ISO 28000 audits from 2026 onwards. Let us first dwell on what 2025 taught the industry and look at the key audit lessons:

  1. Risk assessments were static in a dynamic threat environment. Audits conducted during 2025 repeatedly identified a reliance on periodic, document-driven risk assessments. While these assessments were often well-structured and aligned with ISO 28000 Clause 4 (Security risk assessment and planning), they frequently failed to reflect rapidly changing threat conditions.

ISO 28001 emphasizes that risk assessment should be an ongoing process, responsive to changes in threat, vulnerability, and consequence. In practice, however, many organizations treated risk reviews as annual or biennial events, disconnected from real-time intelligence, incident trends, or geopolitical developments.

The lesson for auditors was clear, conformity to the process was present, but the intent of continual risk awareness was not fully realized.

  1. Limited visibility beyond tier-1 suppliers. A second consistent audit finding in 2025 was the narrow scope of supplier security controls. Organizations could demonstrate security requirements for direct suppliers yet had little understanding or assurance of security practices deeper within the supply chain.

ISO 28001 explicitly recognizes the need to consider the full supply chain, including subcontractors and service providers, when establishing security plans and controls. Despite this guidance, audits revealed that supplier evaluation mechanisms often stopped at contractual clauses, with minimal follow-up, verification, or performance monitoring.

Security incidents originating in Tier-2 or Tier-3 suppliers highlighted the inadequacy of superficial supplier controls and reinforced the need for more robust assurance mechanisms.

  1. Cyber risks were poorly integrated into the supply chain Security. Although ISO 28000 is not a cybersecurity standard, 2025 audits increasingly revealed that cyber vulnerabilities were among the most significant enablers of supply chain disruption. Cargo tracking systems, access control platforms, vendor portals, and logistics planning tools were all identified as potential attack vectors. With harmonized structure (HS) it was presumed that an integrated management system approach could answer this but organizations did not integrate ISO 27001 and ISO 28001 by and large.

ISO 28001 encourages organizations to consider all relevant threats to the supply chain, including those affecting information and communication systems. Yet audits frequently found a disconnect between physical security management and information security governance, with limited coordination between security and IT functions.

This gap did not necessarily result in formal nonconformities, but it raised serious questions about the effectiveness of the overall security management system.

  1. Business continuity planning lacked supply chain realism. Many organizations could demonstrate alignment with business continuity frameworks and, in some cases, certification to ISO 22301 (Business Continuity). However, audits in 2025 showed that supply-chain-specific disruption scenarios were rarely tested.

ISO 28001 stresses the importance of preparedness and response planning based on realistic threat scenarios. Yet exercises involving port closures, border restrictions, supplier insolvency, or regulatory intervention were the exception rather than the rule. The result was a gap between documented preparedness and demonstrated capability, one that became increasingly visible to experienced auditors.

Based on these lessons from 2025 I think the audit focus areas for 2026 and beyond should consider:

  1. Going from risk identification to risk intelligence. From 2026 onwards, auditors will need to place greater emphasis on how organizations maintain the ongoing validity of their risk assessments. ISO 28000 Clause 4, supported by ISO 28001 guidance, implicitly requires organizations to monitor changes that could affect supply chain security risks. Audits should therefore examine:
  • The use of internal and external intelligence sources.
  • Defined triggers for risk reassessment.
  • Evidence that changes in risk lead to timely management action.

The audit question is shifting from “Do you have a risk assessment?” to “How do you know your risk assessment reflects today’s reality?”

  1. Supplier security assurance, not just evaluation. ISO 28001 provides detailed guidance on supplier security planning, including differentiation based on criticality and risk exposure. In 2026, audits will increasingly probe how supplier security requirements are implemented, monitored, and enforced. Key audit considerations will include:
  • Supplier segmentation and prioritization.
  • Proportionate security controls.
  • Evidence of supplier audits, self-assessments, or performance reviews.
  • Corrective action and escalation when requirements are not met.

Supplier security must be demonstrable and sustained, not assumed.

  1. Integration of cyber and physical security controls. Auditors should expect to see clearer alignment between ISO 28000 systems and information security frameworks such as ISO/IEC 27001. ISO 28001 supports this integration by recognizing information flow and system integrity as essential elements of supply chain security. Audit focus areas will include:
  • Identification of cyber-enabled supply chain risks.
  • Coordination between security and IT incident response.
  • Protection of logistics data, tracking systems, and access controls.

While ISO 28000 audits will not become cyber audits, unmanaged cyber dependencies will increasingly undermine audit confidence.

  1. Testing, exercises, and demonstrated preparedness. In 2026 and beyond, documented plans will carry less weight without evidence of testing. ISO 28001 places strong emphasis on preparedness, response, and recovery capabilities. Therefore, auditors should look for:
  • Scenario-based exercises relevant to the organization’s supply chain.
  • Participation by relevant internal and external stakeholders.
  • Lessons learned and system improvements following exercises.

Preparedness is best demonstrated through practice, not paperwork.

  1. Governance and leadership accountability. A notable trend emerging from late-2025 audits was increased attention to top management involvement. ISO 28000 requires leadership commitment, and ISO 28001 reinforces the importance of governance in sustaining effective security management. Audits in 2026 will increasingly examine:
  • Management review outputs related to supply chain security.
  • Resource allocation decisions.
  • Evidence of board or senior leadership awareness of key risks.

Supply chain security is no longer solely an operational concern; it is a matter of organizational governance. Therefore, implications for auditors and organizations are:

  1. For auditors, the coming years will demand deeper understanding of risk dynamics, supply chain complexity, and the convergence of physical and digital threats. Checklist-based auditing will be insufficient where resilience and adaptability are the true measures of effectiveness.
  2. For organizations, ISO 28000 should be repositioned as a strategic risk management framework. Investment in intelligence, supplier assurance, and realistic testing will not only support certification outcomes but also strengthen operational resilience.

In conclusion I would say, based on QMII experience that what 2025 has taught us is that supply chain security management systems fail not because organizations lack procedures, but because those procedures are not designed for volatility. As we move into 2026 and beyond, ISO 28000 audits must therefore measure more than conformity, they must assess resilience.

ISO 28001 provides the guidance needed to make this transition. The challenge for both auditors and organizations are to apply that guidance with realism, discipline, and strategic intent.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

AS9100 for Tier-2/3 Suppliers: Minimum-Viable Risk & Special Process Control Without Gridlock

AS 9100 is applicable to any organization as a choice but is often a business demand. Aerospace is a vast field and has major and minor players. Does it therefore imply that tier 2 and tier 3 suppliers should go through the same documentation burden as a primary aerospace organization? This is a dilemma faced by tier 2/3 suppliers. I have often thought about this. This short article based on QMII experience is specifically written for AS9100 Tier-2/3 Suppliers and how they can maintain the balance between control and still maintain agility and meet the requirements of the standard.

Tier-2 and Tier-3 aerospace suppliers face a unique dilemma, the need to meet AS9100’s rigorous expectations while working with limited resources and tight delivery schedules. Customer flow-downs, documentation demands, and special-process scrutiny can quickly overwhelm small teams. The key challenge is achieving effective control without unnecessary bureaucracy, preserving the agility that keeps smaller suppliers competitive. This special article is aimed at this need of the tier 2/3 suppliers.

The supplier’s challenge in aerospace quality comes from the aerospace customers bringing layers of requirement complexity, unique quality clauses, FAIR specifics (First Article Inspection Report, and the broader process called First Article Inspection (FAI), special-process certifications, customer portals, and documentation formats. These customer-specific expectations often exceed the base AS9100 standard and force Tier-2/3 suppliers to interpret, prioritize, and integrate a landscape of varied demands. Without a structured approach, they risk creating bloated systems that satisfy auditors on paper but hinder production flow.

Understanding AS9100 Clause 8 – operational controls is therefore essential. Clause 8 is the operational heart of AS9100, setting expectations for planning, process control, risk mitigation, and configuration management. It emphasizes that conformity comes from effective planning and controlled execution, not from sheer volume of documents. Suppliers must ensure that personnel have the right information at the right time, that processes are validated where outcomes cannot be fully verified after the fact, and that changes are managed with discipline. For small suppliers, the goal is implementing these controls proportionally to risk, not copying OEM (original equipment manufacturers)-level tier 1 systems.

Minimum-Viable Risk (MVR) must be considered as a pragmatic interpretation of AS9100. AS9100 demands risk-based thinking, but many small suppliers interpret this as “more forms” instead of “better decisions.” MVR provides a method to match controls to actual consequences. It prevents systems from becoming document-heavy while maintaining the safeguards needed for aerospace.

Basic MVR principles include:

  1. Identifying what can truly go wrong (escape, defect, missed requirement).
  2. Assessing the severity of consequence.
  3. Matching control strength to risk severity—not habit or tradition.
  4. Eliminating duplicate or ritualistic checks.
  5. Documenting the rationale for proportional controls.

MVR (monitoring, verification, and reporting) is simplicity with discipline and is the heart of AS9100 done well. It includes applying MVR to special processes without gridlock. Special processes, like welding, heat treat, coatings, NDT (nondestructive testing), bonding pose inherently higher risks because results cannot be fully verified after production. However, small suppliers can maintain strong control without drowning in paperwork. They should control inputs, not layers of signatures. Validate equipment capability, freeze key parameters, ensure personnel competency, and maintain controlled settings. Excess signatures do not improve quality, controlled inputs do.

The tier 2 and 3 suppliers should build process ownership. Escapes in special processes usually stem from incorrect settings, outdated drawings, or tribal knowledge. An escape is a defect that leaves your organization and reaches the customer. A single-point accountability model, owned by the welding lead, NDT supervisor, or coating tech reduces error pathways better than multiple inspectors. Also, use of one-page critical parameter sheets condenses travelers into one-page sheets listing key variables, limits, and required verifications. This approach focuses on what actually matters to conformity.

Another important organizational priority of tier 2/3 suppliers (AS 9100 clause 4.4.1) is to right size the QMS to their risk level. AS9100 allows flexibility, and small suppliers should embrace it. Not every process requires the same level of documentation, inspection, or validation.

  • Low-risk machining or simple assembly can rely on straightforward checks.
  • High-risk special processes need tighter controls, but not excessive forms.
  • Different supplier tiers have different expectations; Tier-3 machining houses need far less documentation than Tier-1 system integrators. 
  • A right-sized QMS is efficient, compliant, and scalable.

Then there is the use of practical supplier evaluation methods. Supplier oversight does not have to involve 12-page questionnaires or annual onsite audits. AS9100 encourages objective, data-driven oversight:

  • On-Time Delivery (OTD).
  • NCR (non-conformity report) and escape trends.
  • Responsiveness to containment.
  • Corrective action effectiveness.

This approach is more reliable than generic forms and lets purchasing focus on high-risk, high-impact suppliers.

 

Then there are the common audit weaknesses in tier suppliers. QMII’s audit experience reveals recurring issues across Tier-2/3 organizations:

  • Manuals copied from templates that do not match actual practice.
  • Weak configuration control, especially in revision management.
  • Inconsistent traceability in special processes and outsourced steps.
  • Internal audits that check boxes instead of evaluating system effectiveness.
  • Training records that prove attendance but not competency.
  • Excessive documentation without actual operational control.

These weaknesses stem not from lack of effort, but from systems that were built to “pass audits” rather than ensure reliability.

Using MVR to reduce escapes and customer returns. Most escapes involve incorrect flow-downs, poor configuration management, or over-reliance on manual documentation. MVR shifts focus from detection to prevention, reducing escapes by simplifying controls and strengthening process discipline. Early requirement clarification, targeted training, and controlled process inputs all contribute to fewer customer complaints and more predictable performance.

As an example, perhaps a recommendatory timeline from QMII for consideration could be for a Tier-2/3 implementation blueprint (90 Days) would be three phased. Phase 1 – Diagnose (Weeks 1–3).  Map critical processes, identify friction points, and assess risk using MVR. In Phase 2 simplify (Weeks 4–8), streamline travelers, create one-page control sheets, and combine competency and training logs. Finally in Phase 3 – reinforce (Weeks 9–12), clarify process ownership, audit for effectiveness, and pilot new controls. This, I think, builds a lean, compliant AS9100 system with predictable output.

In conclusion and as a call to action I would say a streamlined, risk-aligned AS9100 system allows Tier-2/3 suppliers to maintain compliance without sacrificing agility or productivity. By matching control depth to risk, strengthening special-process discipline, and using data-driven supplier monitoring, organizations can reduce escapes, satisfy customers, and maintain competitive flow.

For suppliers looking to strengthen their capability, QMII offers AS9100 auditor training that emphasizes process-based auditing, practical system improvement, and real-world risk management—equipping teams to build QMSs that are both compliant and efficient.

Procedure, Work Instruction, or Flowchart?

-by Dr. IJ Arora

The choice between writing a procedure or a work instruction is an essential decision when designing a management system. Clause 4.4.1 of ISO 9001:2015 (as well as all the ISO management system standards using the harmonized structure) requires the establishment and implementation of a management system. This management system will have procedures and work instructions and further down the hierarchy, checklists and forms.

Processes can be actualized in many forms. Today, mapped processes make it easy to visualize the functioning of the process. This is an important distinction in quality management systems based on ISO 9001—or for that matter any sector-specific standard like those dedicated to management within maritime, aerospace, etc. Many organizations struggle with when to write a procedure, when to write a work instruction, and how and when a flowchart should be used.

I think the core difference between a procedure and a work instruction is that a procedure answers the question, “What happens and who does it?” A procedure defines the process, its purpose, its sequence (clause 4.4.1b), and who is responsible for the work, perhaps as process owners (clause 4.4.1e). It answers what is to be done, when it must be done, who is responsible, and why it matters. The flowchart then helps visualize the inputs and outputs that flow between the steps.

What is a procedure and how it is used?

A procedure does not tell someone how to do a task; it simply describes the steps or stages necessary to accomplish it. I think of the procedure as the blueprint of the workflow. Therefore, I would recommend using the procedure when multiple people or departments are involved, when there is decision-making or sequencing, when the process crosses functional boundaries, and when documenting the process supports consistency, audits, or training. The procedure is also best when regulatory bodies expect clearly defined processes.

What is a work instruction and how is it used?

On the other hand, a work instruction shows stakeholders how exactly a task is to be accomplished. A work instruction “goes into the weeds” to the extent required by the workforce (depending on their confidence, competence, knowledge, and so on). It describes specific methods, often at a deep level of detail. It answers questions such as:

  • “How do I perform this task?”
  • “What tools, equipment, settings, forms, and/or software steps are required?”
  • “What are the acceptance criteria?”
  • “What do I check and how do I measure performance?”

Remember, work instructions are intended to be simple, direct documents for use by the workforce. Use them when:

  • A task requires technical, step-by-step details
  • Training new personnel
  • Incorrect execution can create quality or safety risks
  • Standardization is essential
  • Variation in execution must be eliminated

What is a flowchart and how is it used?

Flowcharts can technically be used to support both procedures and work instructions, but I generally recommend their use in conjunction with procedures. This helps make the procedure visual by mapping the 50,000-foot view of a process. A flowchart is ideal when the process has multiple decision points, parallel paths, several departments interacting, and inputs/outputs that must be made clear. The flowchart helps avoid the confusion that can come when procedures are described in long paragraphs. Flowcharts make complex processes easy to understand immediately. I therefore believe in flowcharting a procedure when the process needs high-level clarity, the sequence matters, when an organization wants to show interactions between departments, when it supports risk-based thinking, and when you want to simplify training for new personnel.

Flowcharts work best for document control, non-conformances, and corrective action processes, purchasing and supplier management, production scheduling, quality inspection, and testing flows and change management processes (as seen in clauses 5.3e, 6.3., 8.2.4, 8.3.6, and 8.5.6). Flowcharts do not replace work instructions; they complement them.

Final thoughts

To sum up how these tools work together, the practical document hierarchy an organization could consider starting with policy (and why that policy exists), move into documenting the procedure (preferably supported by a flowchart) to convey what happens and in what order, and then crafting work instructions to clarify how to carry out specific tasks. Finally, document everything through records and forms to provide evidence that the work was performed.

All this should connect as a system where a flowchart procedure should describe the process, a work instruction explains each critical task, and the documented information provides traceability. Performance monitoring (clause 9) can be documented via procedures, work instructions, and flowcharts.

 

Note – The above article was recently featured in an Exemplar Global publication ‘The Auditor’. 

ISM Code to Bridge the Shore – Ship Gap: Making SMS a Living System

I take pride on my experience as I work with our maritime clients emphasizing the personal perspective from both below and above the surface of this ocean. My view of the ISM Code is shaped by a life at sea. I spent good 22 years of the early part of my career in the Indian Navy, eventually commanding two F-class submarines and later serving on India’s first nuclear submarine a Charlie II. After leaving the Navy, I served for a decade as Master in the mercantile marine. Then as a VP in the second largest ship registry, the Liberian Flag for 3 years and now as the leader of the QMII team. I have seen safety management from the control room of a submarine and from the bridge of a merchant ship, in fair weather and in crisis. These experiences have convinced me that a Safety Management System only works when it is lived by the people who must make decisions in real time, far from shore support.

I still remember standing on the bridge of a merchant vessel, facing commercial pressure to sail on schedule while weather and equipment concerns suggested otherwise. The manuals and procedures were on board, but what mattered in that moment was whether the company truly backed me and my Master’s judgment. That is where the real test of any SMS lies, not in what is written, but in the support given when difficult decisions must be made.

Having sailed for many years, I know how isolating a tough decision at sea can feel. A good DPA is not just a name in the manual but a trusted voice on the other end of the line, someone the Master can call at 0200 hours and speak openly with. When that relationship exists, the SMS becomes real; when it doesn’t, the paperwork quickly loses relevance on board.

After a lifetime at sea and many years working ashore with companies to implement the ISM Code, and finally leading QMII for over two decades in training, auditing and consulting in management systems, I remain convinced of one thing that the Code itself is not the problem. The real issue is whether we choose to make the SMS a living system that respects the realities of those at sea. When shore and ship learn to listen to each other through the SMS, we honor not just compliance requirements, but the professionalism and lives of the people who sail our ships.

More than 25 years after the ISM Code became mandatory, the International Safety Management (ISM) Code is still too often treated as a paper exercise. Shore offices produce manuals, checklists and forms; ships receive them, file them, and do their best to keep up. The result is a familiar complaint from both sides, “The system is for auditors, not for us.”

Yet the ISM Code was never intended to create a paperwork gap between shore and ship. It was meant to bridge that gap by providing a common safety language and a shared framework for decision-making. When understood and implemented as a living system, the Safety Management System (SMS) becomes exactly that bridge. I always recollect the curt observation by Justice Sheen post the sinking of the Herald of Free Enterprise: “…. I see a disease of sloppiness at every level of the hierarchy….”. His direct pointer at having a management system brought us the ISM Code connecting to the SOLAS.

The ISM Code’s original Intent was to have a system that connects people. The ISM Code’s purpose is clear: to provide an international standard for the safe management and operation of ships and for pollution prevention. The Code defines the Safety Management System as a structured and documented system enabling company personnel to implement the company’s safety and environmental protection policy effectively.  From the beginning, the Code placed both shore and ship within the same system. Company objectives in section 1.2 of the ISM Code include:

  • providing safe practices in ship operation and a safe working environment,
  • assessing risks to ships, personnel and the environment and establishing safeguards, and
  • continuously improving safety management skills of personnel ashore and aboard ships.

These are not separate objectives for two separate worlds. They are shared obligations, achievable only when the SMS genuinely links the office and the vessel.

So where then does the gap come from? Despite this intent, many organizations experience a shore–ship divide in their SMS.

  • On shore, staff may focus on satisfying external auditors, producing beautifully formatted procedures that look good in a DOC audit but are hard to use in real operations.
  • On board, crews often experience the SMS as extra work: duplicative checklists, complex forms, and procedures that do not reflect the realities of weather, port pressure and human limitations.

When this happens, several symptoms appear:

  • “Cut-and-paste” risk assessments that no one believes in.
  • Non-conformities written in audit language instead of operational language.
  • Masters and Designated Persons Ashore (DPAs) communicating mainly for certification, not for learning.

The result is an SMS that is formally compliant but functionally weak—it exists on paper but not in daily decision-making. The SMS must be a living system. To bridge the gap, we must return to a simple idea, the SMS is not a manual. It is the way the organization manages risk and work, documented so it can be repeated, audited and improved. A living system has several characteristics:

  • Owned by users, not by paperwork Procedures and checklists are written in the language of the people who use them. Crew and shore staff participate in their development and revision. Guidance documents are concise, operational and easy to find.
  • Fed by real feedback The Code requires procedures for reporting accidents and non-conformities, and for internal audits and management reviews as functional elements of the SMS. In a living system, these are not compliance rituals but mechanisms for learning. Near misses, hazardous observations and improvement suggestions from crew are actively encouraged, analyzed and acted upon.
  • Adaptable, not frozen, clause 12 of the Code calls for review and evaluation of the SMS.
    A living SMS changes in response to new risks, technology, trade patterns and lessons learned. Revision is continuous, not something done hurriedly before an audit.
  • Transparent roles and communication The Code requires defined levels of authority and lines of communication between shore and shipboard personnel. In a living system, these lines are not just organograms—they are trusted relationships. Masters feel supported, not second-guessed. The DPA is accessible, respected and known by name, not just as a title in the manual.

 The DPA then should be the human bridge. Perhaps the most powerful bridging mechanism in the ISM Code is the requirement that every company designate a person or persons ashore with direct access to the highest level of management (ISM Code clause 4).

In many organizations, the Designated Person Ashore (DPA) becomes either:

  • a paper coordinator, chasing signatures and tracking audits, or
  • a firefighter, reacting to incidents and port state control findings.

To make the SMS a living system, the DPA must instead function as a system integrator:

  • Listening systematically to ship feedback and ensuring it reaches senior management.
  • Challenging shore practices that create unrealistic demands on ships.
  • Ensuring that risk assessments and procedures reflect actual operations, not office assumptions.
  • Facilitating honest discussions after incidents—not searching for blame but for system weaknesses.

In short, the DPA should be the voice of the ship in the boardroom and the voice of the system on the ship.

The companies should plan practical steps to bridge the shore–ship gap. Companies that wish to transform a static SMS into a living one can take several practical steps as to co-create procedures with ship staff by involving the masters, officers and ratings when developing or revising procedures. I call it capturing the “as-is” of the system in preference to throwing the ‘baby with the bath water” by simply adopting a template. Pilot new checklists on board before formal approval. Ask: “does this help you do the job safely under time pressure?” If not, redesign. Management systems are not etched in stone. They should be open, flexible and adoptable to change.

Train to be competent and for understanding, not just for compliance. Move beyond “read and sign” familiarization. Use case studies, incident reviews and simulations that connect ISM clauses with real operational dilemmas. Emphasize why a procedure exists, not just how to follow it.

Most importantly, simplify and prioritize. The ISM Code specifies functional requirements, not thickness of manuals. Focus on critical operations and major risks; remove redundant or overlapping forms. A smaller, well-used SMS is better than a massive, ignored one. While doing this, also strengthen feedback loops. Make incident and near-miss reporting simple and non-punitive. Provide feedback to the crew on what was learned and what changed as a result. When people see that speaking up leads to improvement, not punishment, the system comes alive.

Remember data drives risk and trends and makes an organization proactive. Use data—and stories. Combine quantitative indicators (deficiencies, delays, injuries) with qualitative insights (crew narratives, master’s reviews). This blended view gives a more complete picture of safety performance and culture.

A change from compliance culture to learning culture must be brought in to create an environment for quality, safety, security and continual improvement. Port State Control statistics show that ISM-related deficiencies remain among the most frequently reported issues worldwide. This suggests that many SMSs still operate at a minimum compliance level. Bridging the shore–ship gap means moving toward a learning culture, where:

  • Deviations are signals to improve the system, not just to correct the individual.
  • Masters are empowered to exercise their overriding authority and supported by the shore organization with resources on as needed basis.
  • Top management sees the SMS not as a cost, but as an asset that protects people, ships, reputation and the marine environment.

In conclusion I would repeat that making the Code work as intended is the need. Not just talk but walk the talk. The ISM Code gave the maritime industry a powerful framework. It defined objectives, clarified responsibilities, and required a documented Safety Management System (SMS) that connects shore and ship. The challenge now is not to “comply” with the Code, but to realize its intent.

When the SMS is treated as a living system—owned by its users, nourished by feedback, continually adapted and genuinely connecting shore and ship—it becomes what the Code envisioned:

  • a bridge between management and operations,
  • a driver of safety and environmental protection, and
  • a practical expression of the company’s values at sea and ashore.

The choice is ours: an SMS that exists for certificates, or an SMS that saves lives, protects the environment, and unites shore and ship in a common purpose.  

 

About the Author

This article was written by Inderjit “IJ” Arora, Chairman, Board of Directors at QMII. With more than 30 years’ experience spanning military service, merchant marine and civilian industries, he is an Exemplar Global-certified lead auditor and member of the U.S. TAG to ISO/TC 176 (the ISO 9000 family of standards). IJ holds an MBA from The College of William & Mary and an MSc in Defense Studies, and he brings a unique leadership and crisis-management background into quality systems consulting. He specialises in transforming management-system certification into a strategic advantage for organisations.